High urgency

HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information

Detected July 29, 2026 · in Healthcare AI Regulation (FDA / ONC)

HHS proposes to strengthen HIPAA Security Rule cybersecurity requirements for ePHI, with new mandates for asset inventory, risk analysis, encryption, multi-factor authentication, and more. Comments due by March 7, 2025.

Aforeworn detected this change in the Healthcare AI Regulation (FDA / ONC) space on July 29, 2026 and published this briefing so affected operators are forewarned rather than caught off guard. It is rated High urgency. All HIPAA-covered entities and business associates that create, receive, maintain, or transmit electronic protected health information (ePHI), including health systems, medical device companies, health tech startups, and digital health compliance teams. should confirm how it applies to their specific situation before acting. There is a time constraint attached: Comments due March 7, 2025 (60 days after publication on January 6, 2025).. Acting after that point can mean penalties, a lapsed licence, or lost eligibility — exactly the kind of surprise Aforeworn exists to prevent. Aforeworn monitors Healthcare AI Regulation (FDA / ONC) continuously and turns every detected change into a plain-English briefing like this one, so you always know first. Forewarned is forearmed.

What changed

The proposed rule would require: (1) a written asset inventory and network map; (2) updated risk analysis including all ePHI systems; (3) encryption of ePHI at rest and in transit; (4) multi-factor authentication for any system accessing ePHI; (5) vulnerability scanning and penetration testing; (6) audit controls and logging; (7) contingency plan testing; (8) annual compliance audits; and (9) 24-hour breach notification to HHS. No specific dollar amounts or penalties are stated in the excerpt.

Who it affects

All HIPAA-covered entities and business associates that create, receive, maintain, or transmit electronic protected health information (ePHI), including health systems, medical device companies, health tech startups, and digital health compliance teams.

What you must do

Review the full NPRM and submit comments by the deadline. Begin gap analysis against proposed requirements to prepare for eventual compliance.

Deadline

Comments due March 7, 2025 (60 days after publication on January 6, 2025).

Source: https://www.federalregister.gov/documents/2025/01/06/2024-30983/hipaa-security-rule-to-strengthen-the-cybersecurity-of-electronic-protected-health-information

Never miss a change like this again

Aforeworn watches Healthcare AI Regulation (FDA / ONC) around the clock and alerts you the moment a rule moves — with a plain-English brief on what to do.

Start your free trial

Related changes in Healthcare AI Regulation (FDA / ONC)